Methods, devices, and systems for secure provisioning, transmission, and authentication of payment data
Abstract
Devices, systems, and methods for securely converting a user's existing static payment card data into dynamic card data that can be authenticated by card issuers or by a stand-in service provider, such as a payment network or processor without requiring the card issuers to make infrastructure changes. The dynamic data can be provisioned onto a magnetic secure transmission device (MST) either directly from a card issuer or using a swiper type device. Devices, systems, and methods are also disclosed for securely provisioning a dynamic card onto the MST by the card issuer. These dynamic cards may be used to transmit modified one-time-use card track data from the MST to a point of sale using a dynamic-CVV methodology to provide higher levels of security during a transaction.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for creating dynamic card data, comprising:
receiving, by a device, card track data; encrypting, by the device, the card track data using a first key; sending, by the device, the encrypted card track data to a server; receiving, by the device, a working key; generating, by the device, modified card track data including a time-dependent CVV using the working key; and sending, by the device, the modified card track data to a point of sale terminal or causing the modified card track data to be displayed to a user for use in an e-commerce transaction.
2 . The method of claim 1 , wherein an expiration date, a registered primary account number, or a portion of a discretionary field of the modified track data indicates to a card issuer or a third party service provider that the modified card track data is dynamic-CVV (dCVV) card track data and authorization is to be performed in a dCVV mode.
3 . The method of claim 1 , wherein the sending the modified card track data to the point of sale terminal includes sending the time-dependent CVV, and a dynamic mode indicator.
4 . The method of claim 3 , wherein the dynamic mode indicator is a primary account number, an expiration date, or a separate dynamic mode indicator of the modified track data.
5 . The method of claim 4 , wherein the dynamic mode indicator indicates to a card issuer or third party service provider, that the modified card track data is dynamic-CVV (dCVV) card track data and authorization is to be performed in a dCVV mode.
6 . The method of claim 1 , wherein the device is a magnetic stripe storage and transmission device or a mobile communication device.
7 . A method for provisioning dynamic financial card data by issuer, comprising:
receiving, by a server, a request for provisioning card track data; requesting, by the server, an authentication of a user corresponding to the card track data from a card issuer server, wherein the card issuer server corresponds to a card issuer of the card track data; receiving, by the server, an authentication result from the card issuer server; and generating, by the server, a working key for the generation of dynamic card track data.
8 . The method of claim 7 , wherein the requesting the authentication of the user from the card issuer server includes sending a primary account number and at least one of a CVV-2, a name, a date of birth, a username and password, and an answer to a challenge question to the card issuer server for authentication.
9 . The method of claim 7 , further comprising securely sending the working key to a wallet server.
10 . The method of claim 7 , further comprising receiving a request for verification of a dynamic-CVV (dCVV) in response to initiation of a payment transaction, wherein the dCVV is based on the working key.
11 . The method of claim 10 , wherein the receiving the request for verification of the dCVV includes receiving a primary account number, an expiration date, a service code, a time-stamp, and a mode indicator.
12 . The method of claim 11 , further comprising comparing the received time-stamp with a stored time-stamp or current time on the server for verifying a transaction.
13 . The method of claim 12 , further comprising sending an authorization failure in response to the stored time-stamp or current time corresponding to a time greater than the received time-stamp.
14 . A method for performing dynamic-CVV (dCVV), comprising:
generating, by a server, a working key for card track data; receiving, by a magnetic stripe storage and transmission device (MST), the working key; generating, by the MST, modified card track data including a dCVV component based on original card track data, a time-stamp or counter and the working key; sending the modified card track data to a point of sale terminal or e-commerce website for payment processing; receiving, by the server, a request for verification of the dCVV from a card issuer server or a third party service provider in response to initiation of the payment processing, wherein the request includes the modified card track data; performing, by the server, a verification of the dCVV component; and sending, by the server, a verification failure or final verification based on the verification of the dCVV component.
15 . The method of claim 14 , wherein the modified card track data includes the dCVV component, a primary account number, an expiration date, a service code, the time-stamp or counter, and optionally a separate mode indicator when the expiry date or the primary account number is not used to indicate that authorization is to be performed in a dCVV mode.
16 . The method of claim 15 , wherein the mode indicator indicates to the card issuer server that the modified card track data is dCVV card track data and authorization is to be performed in a dCVV mode.
17 . The method of claim 15 , wherein the performing the verification includes comparing a received time-stamp or received counter with a stored time-stamp or a current time of the server or stored counter.
18 . The method of claim 17 , wherein the sending the verification failure or final verification includes sending the verification failure in response to the stored time-stamp or current time of the server corresponding to a time greater than the received time-stamp.
19 . The method of claim 15 , wherein the performing the verification includes:
independently computing, by the server, a dCVV vale using the working key; and comparing the computed dCVV value with the dCVV component.
20 . The method of claim 19 , wherein the sending the verification failure or final verification includes sending the final verification in response to the computed dCVV value matching the received dCVV component.
21 . The method of claim 14 , further comprising sending, by the server, the original card track data to the card issuer server for processing via the card issuer server's normal processing methods to complete a transaction, wherein the original card track data corresponds to data of a card issuer corresponding to the card issuer server.Join the waitlist — get patent alerts
Track US2015371234A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.